APPLE-SA-2011-03-09-2Vendor advisory
http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.html CVE-2011-0167
WebKit 1.2.x - Local Webpage Cross Domain Information Disclosure
Record summary
CVE-2011-0167 has a selected CVSS score of 4.3; EIP currently links 1 catalogued exploit.
Description
The windows functionality in WebKit in Apple Safari before 5.0.4 allows remote attackers to bypass the Same Origin Policy, and force the upload of arbitrary local files from a client computer, via a crafted web site.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBWebKit 1.2.x - Local Webpage Cross Domain Information DisclosureExploitDB exploitby Aaron SigelNot analyzed1 file
References
5support.apple.comConfirmation
http://support.apple.com/kb/HT4566 46816vdb entry
http://www.securityfocus.com/bid/46816 1025183vdb entry
http://www.securitytracker.com/id?1025183 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2011-0167